Microsoft Defender for Endpoint
Endpoint protection

Turn on network protection

In brief

The article now specifies supported Windows versions, Microsoft Defender Antivirus requirements, Windows Server management options, licensing considerations, and recommends testing audit mode before block mode.

What Defender admins need to know

Verify these prerequisites and use audit mode before enabling blocking, especially on Windows Server.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Turn onConfigure network protection in Microsoft Defender Antivirus

Network protection helps to prevent usersapps from using any applicationconnecting to access dangerous domains that might host phishing scams, exploits, and other malicious content on the internet. This article describes how to enable andSecurity administrators can configure network protection by using Microsoft Intune, the Microsoft Defender for Endpoint Security Settings Management,portal, mobile device management (MDM), Microsoft Intune,Configuration Manager, Group Policy, PowerShell, and Mobile Device Management (MDM). You canor PowerShell.

Before you enable network protection in block mode, use audit mode in a test environment to view whichidentify apps that would be blocked before enabling network protection.blocked.

For details, see Network filtering configuration options

Before you begin, review the supported operating systems and Microsoft Defender Antivirus requirements in Prerequisites.

Prerequisites

Supported operating systems

Network protection is supported onThe procedures in this article apply to the following operating systems:

Network protection is also supported on other platforms. For platform-specific instructions, see Network protection for Linux and Network protection for macOS.

Microsoft Defender Antivirus requirements

Network protection requires Microsoft Defender Antivirus in active mode with real-time protection enabled.

Windows Server requirements

Configure network protection in Microsoft Intune

[!INCLUDE intune-recommended-separate-product]

You can enable network protection in Microsoft Intune by using an antivirus policy or a security baseline.

Configure network protection in Intune using endpoint security policies

To configure network protection by using a Microsoft Intune endpoint security Antivirus policy, see Create endpoint security policies or Modify existing policies (links open new tabs in the Intune documentation).

When you create the policy, use these specific settings:

When you create or modify the policy, use these specific settings on the Configuration settings tab:

  • Enable network protection

    To enable network protection, you can use any in the Defender section: Select one of the methods describedfollowing values:

    • Enabled (block mode): Blocks connections to malicious or suspicious domains.
    • Enabled (audit mode): Records network protection events without blocking connections.
    • Disabled: Turns off network protection.
    • Not configured: Leaves the setting unmanaged by the policy.

For more information about Microsoft Defender Antivirus profiles in this article.Intune, see Antivirus policy for endpoint security in Intune.

Configure network protection in Intune using a security baseline

To configure network protection as part of a security baseline in Microsoft Intune, see Create a profile for a security baseline or Edit a security baseline (links open new tabs in the Intune documentation).

When you create the profile, select Microsoft Defender for Endpoint Security Settings Management

Create an endpoint security policy

  1. In the Microsoft Defender portal at https://security.microsoft.com, go to EndpointsBaseline >.

    When you create or modify the profile, use these specific settings on the Configuration managementsettings >tab:

    • Enable Network Protection in the Defender section: Select Enabled (block mode) or Enabled (audit mode).

    For more information about security baselines in Microsoft Intune, see Learn about Intune security baselines for Windows devices.

    Configure network protection in the Microsoft Defender portal

    If your organization manages endpoint security policies in the Microsoft Defender portal, use a Microsoft Defender Antivirus policy to configure network protection.

    For detailed instructions, see Create an endpoint security policy or Edit an endpoint security policy (links open new tabs).

    When you create the policy on the Endpoint security policies. Or, to go directly to page in the Endpoint Security Policies page,Microsoft Defender portal at https://security.microsoft.com/policy-inventory, use https://security.microsoft.com/policy-inventory.

  2. On the Windows policies tab of the Endpoint Security Policies page, select Create new policy.

  3. On the Create a new policy flyout that opens, configure the followingthese specific settings:

    • Select platform: Select Windows.
    • Select template: Select Microsoft Defender AntiVirusAntivirus.

    SelectWhen you create or modify the policy, configure Create policy.

  4. The Create a new policyEnable network protection wizard opens. Onin the BasicsDefender tab, configure the following settings:

    • Name: Enter a unique, descriptive name for the policy.
    • Description: Enter an optional description.

    Select Next.

  5. Onsection on the Configuration settings tab, expand Defender and then select a value for Enable network protection based on operating system:

    • Windows clients and Windows servers: Available values are:tab:

      • Enabled (block mode): Blocks connections to malicious or suspicious domains. Block mode is needed to blockrequired for IP address/address and URL indicators and Web Content Filtering.web content filtering.
      • Enabled (audit mode): Records network protection events without blocking connections.
      • Disabled (Default): Turns off network protection.
      • Not Configuredconfigured: Leaves the setting unmanaged by the policy.
    • For Windows Server 2016 and Windows Server 2012 R2: YouR2, also need to configure theset Allow Network Protection Down Level setting in the Threat Severity Default Action section. Available values are:

      • section to Network protection will be enabled downlevel
      • Network Protection will be disabled downlevel. (Default)
      • Not configured
    • .

      Optional Network Protection settings for Windows clients and Windows servers:The policy also contains the following optional network protection settings:

      • Allow Datagram Processing On Win Server: Available values are:
        • Datagram processing on Windows Server is enabled

        • For server roles that generate high volumes of UDP traffic, select Datagram processing on Windows Server is disabled (Default): We strongly recommend this value for any server roles that generate high volumes of UDP traffic. For example:

          • Domain Controllers
          • Windows. Examples include domain controllers, DNS servers
          • Windows File Servers
          • Microsoftservers, file servers, SQL servers
          • MicrosoftServer, and Exchange servers

          Disabling datagram processing on these servers helps keep the network stable and ensures better use of system resources in high-demand environments. Enabling datagram processing on these servers can reduce network performance and reliability.

        • Not configured

        Server.
      • Disable DNS over TCP parsing
        • DNS over TCP parsing is disabled
        • : Select whether DNS over TCP parsing is enabled (Default)
        • Not configured
        or disabled.
      • Disable HTTP parsing
        • HTTP parsing is disabled
        • : Select whether HTTP parsing is enabled (Default)
        • Not configured
        or disabled.
      • Disable SSH parsing
        • SSH parsing is disabled
        • : Select whether SSH parsing is enabled (Default)
        • Not configured
        or disabled.
      • Disable TLS parsing
        • TLS parsing is disabled
        • : Select whether TLS parsing is enabled (Default)
        • Not configured
        or disabled.
      • [Deprecated] Enable DNS Sinkhole
        • : Select whether DNS Sinkholesinkhole is disabled
        • DNS Sinkhole is enabled. (Default)
        • Not configured
      enabled or disabled.

    When you're finished

    Configure network protection in any MDM solution using the Policy CSP

    The Policy configuration service provider (CSP) enables organizations to configure policies on the Configuration settings tab, select Next.

  6. On the Assignments tab, click in the search box or start typing a group name, and then select it from the results.

    You can select All users or AllWindows devices by using any mobile device management (MDM) solution, not just Microsoft Intune. For more information, see Policy CSP.

    When you select a custom group, you can use that group to include or excludeConfigure network protection by using the group members.EnableNetworkProtection CSP with the following settings:

    When you're finished on the AssignmentsOMA-URI path tab, select: ./Device/Vendor/MSFT/Policy/Config/Defender/EnableNetworkProtection
    NextData type.: Integer
    Value:

    • 0: Network protection is disabled.
    • 1: Network protection is enabled in block mode.
    • 2: Network protection is enabled in audit mode.

    On the Review + create tab, review your settings, and then select Save.

Microsoft Intune

You can enable

Configure network protection in Microsoft Intune using any of the following methods: a security baseline, an Antivirus policy, or a Device configuration profile.

Microsoft Defender for Endpoint Baseline method

Configuration Manager

To configure network protection as part of a security baseline in Microsoft Intune,Configuration Manager, use a Windows Defender Exploit Guard policy. For detailed instructions, see Create a profile for a security baseline (opens in a new tab inCreate and deploy an Exploit Guard policy.

When you create or modify the Intune documentation). When creating the security baseline profile,policy, use these specific settings:

  • BaselineExploit Guard components (new policies only): Microsoft Defender for Endpoint Security BaselineSelect Network protection.
  • Configuration settingsConfigure network protection (new and existing policies): ExpandSelect DefenderBlock and set, Enable Network ProtectionAudit to Enabled (block mode), or Enabled (audit mode)Disabled.

For more information about security baselines

Remove Configuration Manager Exploit Guard settings

When you deploy an Exploit Guard policy by using Configuration Manager, the settings remain on the client if you remove the deployment. The client records Delete not supported in Microsoft Intune, see Learn about Intune security baselines for Windows devices.the ExploitGuardHandler.log file.

After your security baseline profile is createdTo remove the Exploit Guard settings, run the following PowerShell script in the SYSTEM context. The script clears the Defender and assigned, return to this article to continue with Check if network protection is enabled.Exploit Guard MDM policy values, including attack surface reduction rules, controlled folder access, and network protection:

Antivirus policy method

$defenderObject = Get-WmiObject -Namespace "root/cimv2/mdm/dmmap" -Class "MDM_Policy_Config01_Defender02" -Filter "InstanceID='Defender' and ParentID='./Vendor/MSFT/Policy/Config'"

$defenderObject.AttackSurfaceReductionRules = $null

$defenderObject.AttackSurfaceReductionOnlyExclusions = $null

$defenderObject.EnableControlledFolderAccess = $null

$defenderObject.ControlledFolderAccessAllowedApplications = $null

$defenderObject.ControlledFolderAccessProtectedFolders = $null

$defenderObject.EnableNetworkProtection = $null

$defenderObject.Put()

$exploitGuardObject = Get-WmiObject -Namespace "root/cimv2/mdm/dmmap" -Class "MDM_Policy_Config01_ExploitGuard02" -Filter "InstanceID='ExploitGuard' and ParentID='./Vendor/MSFT/Policy/Config'"

$exploitGuardObject.ExploitProtectionSettings = $null

$exploitGuardObject.Put()

Configure network protection by using Group Policy

To configure network protection using a Microsoft Intune Endpoint Security Antivirus policy, see Create an endpoint security policy (opens in a new tab in the Intune documentation). When creating the policy, usedomain environment, follow these settings:steps:

  • Policy type: Antivirus
  • Platform: Windows
  • Profile: Microsoft Defender Antivirus
  • Configuration settings: Set Enable network protection to Enabled (block mode) for enforcement, or Enabled (audit mode) to assess impact before enforcement

For more information about Microsoft Defender Antivirus profiles in Microsoft Intune, see Antivirus policy for endpoint security.

After your Antivirus policy is created and assigned, return to this article to continue with Check if network protection is enabled.

Device configuration profile method

To configure network protection using a Microsoft Intune Device configuration profile, see Add Endpoint protection settings in Intune (opens in a new tab in the Intune documentation). When creating the Device configuration profile, use these settings:

  • Platform: Windows 10 and later
  • Profile type: Templates > Endpoint protection
  • Configuration settings: Expand Microsoft Defender Exploit Guard > Network filtering and set Network protection to Enable or Audit

For more information about the Network protection setting and available values, see Network filtering settings for endpoint protection.

After your Device configuration profile is created and assigned, return to this article to continue with Check if network protection is enabled and alternative deployment methods.

Mobile device management (MDM)

  1. Update Microsoft Defender anti-malware platform to the latest version before you turn network protectionOpen the Group Policy Management Console (GPMC) on or off.your Group Policy management computer.

  2. UseIn the EnableNetworkProtection configuration service provider (CSP) to turn network protection on or off, or to enable audit mode.

Group Policy

Use the following procedure to enable network protection on domain-joined computers or on a standalone computer.

  1. On a standalone computer, go toGPMC console tree, expand Start and then type and select Edit group policy.

    -Or-

    On a domain-joined Group Policy management computer, openObjects in the Group Policy Management Console (GPMC). Right-clickforest and domain that contain the Group Policy Objectobject (GPO) you want to configureedit.

  2. Right-click the GPO, and then select Edit.

  3. In the Group Policy Management Editor, go to Computer configuration and select> Administrative templates.

  4. Expand the tree to > Windows components > Microsoft Defender Antivirus > Microsoft Defender Exploit Guard > Network protection.

    On older versions of Windows, the Group Policy path might have Windows Defender Antivirus instead of Microsoft Defender Antivirus.

  5. Double-click the Prevent users and apps from accessing dangerous websites setting and set the option to Enabled. In the options section, you must specify one of the following options:

    • Block: Users can't access malicious IP addresses and domains.
    • Disable (Default): The Network protection feature doesn't work. Users aren't blocked from accessing malicious domains.
    • Audit Mode: If a user visits a malicious IP address or domain, an event is recorded in the Windows event log. However, the user isn't blocked from visiting the address.
  1. In the Network protection details pane, open Prevent users and apps from accessing dangerous websites.

  2. Select Enabled, and then select one of the following options:

    • Block: Blocks access to malicious IP addresses and domains.
    • Disable (Default): Turns off network protection.
    • Audit Mode: Records an event when a user visits a malicious IP address or domain without blocking access.

    Select OK.

to verify that your Group Policy settings are correct.

Microsoft Configuration Manager

Use the following steps to create and deploy an Exploit Guard policy that enables

Configure network protection by using PowerShell

To configure network protection in Configuration Manager.

  1. Open the Configuration Manager console.

  2. Go to Assets and Compliance > Endpoint Protection > PowerShell on Windows Defender Exploit Guard.

  3. Select Create Exploit Guard Policy from the ribbon to create a new policy.

  4. To edit an existing policy, select the policy, then select Properties from either the ribbon or the right-click menu. Edit the Configure network protection option from the Network Protection tab.

  5. On the General page, specify a name for the new policy and verify the Network protection option is enabled.

  6. On the Network protection page, select one ofclients, use the following settings for the Configure network protection option:

    • Block
    • Audit
    • Disabled
  7. Complete the rest of the steps, and save the policy.

  8. From the ribbon, select Deploy to deploy the policy to a collection.

PowerShell

Usesyntax in an elevated PowerShell to enable, audit, or disable network protection on a device.

  1. On your Windows device, select Start, type powershell, right-click Windowssession (a PowerShell, and then select prompt you opened by selecting Run as administrator.):

    Set-MpPreference -EnableNetworkProtection <Disabled | Enabled | AuditMode>
    
    • Disabled: Turns off network protection.
    • Run the following cmdlet to enableEnabled: Turns on network protection in block mode, which prevents connections to malicious or suspicious domains:domains.

    • AuditMode: Turns on network protection in audit mode, which records events for connections to malicious domains without blocking them.

    To configure network protection in PowerShell on Windows servers, use the following syntax in an elevated PowerShell session:

    • Windows Server 2019 or later:

      Set-MpPreference -AllowNetworkProtectionOnWinServer $true [-AllowDatagramProcessingOnWinServer $false] -EnableNetworkProtection <Disabled | Enabled | AuditMode>
      
    • For Windows Server, use these additional commands:

      Windows Server versionCommands
      2016 or Windows Server 2019 and later2012 R2 with the modern unified solution for Microsoft Defender for Endpoint:
      Set-MpPreference -AllowNetworkProtectionDownLevel $true -AllowNetworkProtectionOnWinServer $true [-AllowDatagramProcessingOnWinServer $false] -EnableNetworkProtection <Disabled | Enabled | AuditMode>
      

      For detailed syntax and parameter information, see Set-MpPreference.

      Verify network protection settings on devices

      Use one of the following methods to verify the network protection settings on a device:

      • PowerShell:

        Run the following command in PowerShell:

        Get-MpPreference | Select-Object EnableNetworkProtection, AllowNetworkProtectionOnWinServer, AllowNetworkProtectionDownLevel, AllowDatagramProcessingOnWinServer
        
        • EnableNetworkProtection:
          • 0: Network protection is off.
          • 1: Network protection is on in Block mode.
          • 2: Network protection is on in Audit mode.
        • AllowNetworkProtectionOnWinServer: On Windows servers, the value should be True.
        • AllowNetworkProtectionDownLevel: On Windows Server 2016
          and Windows Server 2012 R2 with the unified agent for Microsoft Defender for Endpoint
      unified agent, the value should be Set-MpPreference -AllowNetworkProtectionDownLevel $trueTrue
      .
    • AllowDatagramProcessingOnWinServer: On server roles that generate high volumes of UDP traffic, the value should be Set-MpPreference -AllowNetworkProtectionOnWinServer $trueFalse
    • .
  2. Registry Editor:

    1. Open Registry Editor. For example, run regedit.exe.

    2. Go to HKEY_LOCAL_MACHINE > SOFTWARE > Policies > Microsoft > Windows Defender > Policy Manager.

      If that path doesn't exist, go to HKEY_LOCAL_MACHINE > SOFTWARE > Microsoft > Windows Defender > Windows Defender Exploit Guard > Network Protection.

    3. Select EnableNetworkProtection to see the current state of network protection on the device:

      • 0: Network protection is off.
      • 1: Network protection is on in Block mode.
      • 2: Network protection is on in Audit mode.

      :::image type="content" source="/defender/media/95341270-b738b280-08d3-11eb-84a0-16abb140c9fd.png" alt-text="Screenshot of the Network Protection registry key in Registry Editor." lightbox="/defender/media/95341270-b738b280-08d3-11eb-84a0-16abb140c9fd.png":::

    1. (This step is optional.) To set network protection to audit mode, which logs events for connections to malicious domains without blocking them, use the following cmdlet:

      Set-MpPreference -EnableNetworkProtection AuditMode
      

      To turn off network protection, use the Disabled parameter instead of AuditMode or Enabled.

    Check if network protection is enabled

    You can use Registry Editor to check the status of network protection.

    1. Open Registry Editor (for example, run regedit.exe).

    2. Navigate to the following path: HKEY_LOCAL_MACHINE > SOFTWARE > Policies > Microsoft > Windows Defender > Policy Manager

      If that path doesn't exist, navigate to HKEY_LOCAL_MACHINE > SOFTWARE > Microsoft > Windows Defender > Windows Defender Exploit Guard > Network Protection.

    3. Select EnableNetworkProtection to see the current state of network protection on the device:

      • 0 is Off
      • 1 is On
      • 2 is Audit mode

      :::image type="content" source="/defender/media/95341270-b738b280-08d3-11eb-84a0-16abb140c9fd.png" alt-text="Screenshot of the Network Protection registry key in Registry Editor." lightbox="/defender/media/95341270-b738b280-08d3-11eb-84a0-16abb140c9fd.png":::

    Important information about removing Exploit Guard settings from a device

    When you deploy an Exploit Guard policy using Configuration Manager, the settings remain on the client even if you later remove the deployment. If the deployment is removed, the client logs Delete not supported in the ExploitGuardHandler.log file.

    To correctly remove Exploit Guard settings, use the following PowerShell script in the SYSTEM context. This script clears the Defender and Exploit Guard MDM policy values (including attack surface reduction rules, controlled folder access, and network protection) directly on the device through WMI:

    $defenderObject = Get-WmiObject -Namespace "root/cimv2/mdm/dmmap" -Class "MDM_Policy_Config01_Defender02" -Filter "InstanceID='Defender' and ParentID='./Vendor/MSFT/Policy/Config'"
    
    $defenderObject.AttackSurfaceReductionRules = $null
    
    $defenderObject.AttackSurfaceReductionOnlyExclusions = $null
    
    $defenderObject.EnableControlledFolderAccess = $null
    
    $defenderObject.ControlledFolderAccessAllowedApplications = $null
    
    $defenderObject.ControlledFolderAccessProtectedFolders = $null
    
    $defenderObject.EnableNetworkProtection = $null
    
    $defenderObject.Put()
    
    $exploitGuardObject = Get-WmiObject -Namespace "root/cimv2/mdm/dmmap" -Class "MDM_Policy_Config01_ExploitGuard02" -Filter "InstanceID='ExploitGuard' and ParentID='./Vendor/MSFT/Policy/Config'"
    
    $exploitGuardObject.ExploitProtectionSettings = $null
    
    $exploitGuardObject.Put()
    

    See also

    Related content